Impact
The vulnerability allows a malicious project to define a bogus golang.org/fips140 module and, by controlling a GOMODPROXY, serve an arbitrary module that satisfies the toolchain’s trust checks. The build process unpacks the trusted ziphash for the bundled golang.org/fips140 module and constructs its entry in the GOMODCACHE, effectively bypassing checksum verification. An attacker can therefore inject arbitrary code that runs during a Go build, compromising confidentiality, integrity, and potentially availability of the built binary.
Affected Systems
Go toolchain cmd/go is affected. No specific version information is provided; the issue applies to any installation of the Go toolchain that accepts modules from a user‑defined GOMODPROXY and verifies their checksum packages.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the impact is high: an attacker can ship code that executes during compilation. The likely attack vector is an environment where the build user selects or is directed to a malicious GOMODPROXY, allowing the attacker to host the forged golang.org/fips140 module. Without an official CVSS score, its severity remains undetermined, yet the potential for arbitrary code execution warrants a high risk assessment.
OpenCVE Enrichment